Mapping Risk Assessment Strategy for COVID-19 Mobile Apps’ Vulnerabilities

Tanusree Sharma, Hunter A. Dyer, Roy H. Campbell, Masooda Bashir

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Recent innovations in mobile technologies are playing an important and vital role in combating the COVID-19 pandemic. While mobile apps’ functionality plays a crucial role in tackling the COVID-19 spread, it is also raising concerns about the associated privacy risks that users may face. Recent research studies have showed various technological measures on mobile applications that lack consideration of privacy risks in their data practices. For example, security vulnerabilities in COVID-19 apps can be exploited and therefore also pose privacy violations. In this paper, we focus on recent and newly developed COVID-19 apps and consider their threat landscape. Our objective was to identify security vulnerabilities that can lead to user-level privacy risks. We also formalize our approach by measuring the level of risk associated with assets and services that attackers may be targeting to capture during the exploitation. We utilized baseline risk assessment criteria within the scope of three specific security vulnerabilities that often exists in COVID-19 applications namely credential leaks, insecure communication, and HTTP request libraries. We present a proof of concept implementation for risk assessment of COVID-19 apps that can be utilized to evaluate privacy risk by the impact of assets and threat likelihood.

Original languageEnglish (US)
Title of host publicationIntelligent Computing - Proceedings of the 2021 Computing Conference
EditorsKohei Arai
PublisherSpringer
Pages1082-1096
Number of pages15
ISBN (Print)9783030801182
DOIs
StatePublished - 2022
EventComputing Conference, 2021 - Virtual, Online
Duration: Jul 15 2021Jul 16 2021

Publication series

NameLecture Notes in Networks and Systems
Volume283
ISSN (Print)2367-3370
ISSN (Electronic)2367-3389

Conference

ConferenceComputing Conference, 2021
CityVirtual, Online
Period7/15/217/16/21

Keywords

  • COVID-19
  • Mobile apps
  • Privacy risks
  • Threat likelihood

ASJC Scopus subject areas

  • Control and Systems Engineering
  • Signal Processing
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Mapping Risk Assessment Strategy for COVID-19 Mobile Apps’ Vulnerabilities'. Together they form a unique fingerprint.

Cite this